PT-2026-94356 · Internlm · Lmdeploy

·

CVE-2026-92983

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions InternLM LMDeploy versions prior to 0.17.1
Description In DistServe prefill/decode disaggregation mode, the proxy uses user-facing session IDs instead of internal scheduler keys, which prevents the release of scheduler sessions. Unauthenticated attackers can send completion requests to the proxy endpoint, causing unreleased scheduler metadata and memory to accumulate until the prefill worker is terminated due to an out-of-memory condition.
Recommendations Update InternLM LMDeploy to version 0.17.1 or later.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92983

Affected Products

Lmdeploy